CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationHard
A penetration tester is performing reconnaissance against a target organization's web infrastructure. They want to identify all subdomains associated with the primary domain example.com by scraping various public data sources, including search engines, certificate transparency logs, and DNS records. Which command-line tool is best suited for this comprehensive subdomain enumeration?
- AAmass enum -d example.com
- Bnslookup example.com
- Chost -t NS example.com
- Ddig example.com AXFR
Show answer & explanationAnswer & explanation
Correct answer: A. Amass enum -d example.com
Amass is a powerful and comprehensive subdomain enumeration tool that uses various techniques, including scraping search engines, querying certificate transparency logs, and performing brute-force DNS lookups, to discover a wide range of subdomains.
Why the other options are wrong
- B. `nslookup example.com` performs a simple DNS query for the main domain, not a comprehensive search for all subdomains.
- C. `host -t NS example.com` queries for the authoritative name servers of the domain, not for all subdomains.
- D. `dig example.com AXFR` attempts a DNS zone transfer, which is often blocked and only works if misconfigured, not a comprehensive subdomain enumeration method.
Amass for Subdomain Enumeration
A comprehensive open-source tool for attack surface mapping and subdomain enumeration, leveraging various techniques like DNS brute-forcing, scraping, and certificate transparency logs.
- Uses multiple data sources for subdomain discovery.
- Leverages certificate transparency logs.
- Effective for mapping a target's full attack surface.
Memory trick: Amass MASses together all subdomain data for you.